OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change attributes that are intended to be unmodifiable by the user. It is possible to toggle the external flag on/off and change the own token value for a user. It is also possible to edit attributes that are not in the allow list, such as otp_qr and otp_activated. If external users exist in the OpenCTI setup and the information about these users identities is sensitive, the above vulnerabilities can be used to enumerate existing user accounts as a standard low privileged user. This issue has been patched in version 6.4.10.
{
"cwe_ids": [
"CWE-284",
"CWE-657"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24887.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "6.4.8"
},
{
"fixed": "6.4.10"
},
{
"introduced": "0"
},
{
"last_affected": "6.4.10"
}
],
"source": [
"AFFECTED_FIELD",
"CPE_RANGE"
]
}